Sanad.dev
Menu

Bug Bounty

Sanad welcomes good-faith security research that helps protect Software Engineers using our account flow, business workspaces, billing, API access, session timer, and AI access controls.

One free testing week. Create a Sanad test account, then email support@sanad.dev with that account email and your testing plan to request the free testing week. Create a Sanad account.

Scope

The current in-scope Sanad properties are sanad.dev, www.sanad.dev, app.sanad.dev, id.sanad.dev, api.sanad.dev, and ai.sanad.dev. Eligible research includes sign-in and registration flows, account and business authorization boundaries, billing and balance boundaries, API key handling, session start/stop behavior, daily usage limits, rate limits, AI access controls, public pages, and admin surfaces when tested only with accounts you control.

Rewards

Rewards are issued as Sanad access credit after paid access is available. We assign severity based on demonstrated business and user impact, exploitability, affected users, and the quality of the report.

LowAccess credit equivalent to 1 month
MediumAccess credit equivalent to 2 months
HighAccess credit equivalent to 3 months
CriticalAccess credit equivalent to 6 months

Severity guide

Critical

Examples include reliable unauthorized access to another user's registration data, account data, API key material, or AI access; taking over another account; performing admin-only activation or revocation actions without authorization; or a vulnerability that exposes sensitive user data at scale.

High

Examples include bypassing account, balance, business, or session checks to use Sanad AI; the ability to keep an AI session active while the usage timer is not charged; materially extending daily usage without authorization; modifying another user's access status; or accessing another user's limited profile or usage information.

Medium

Examples include account or session weaknesses that require user interaction, cross-site scripting with meaningful account impact, rate-limit bypasses that create measurable service abuse, improper access to non-sensitive metadata, or workflow flaws that let a user gain limited extra paid access or balance benefit.

Low

Examples include low-impact security header issues, low-risk open redirects, self-contained client-side issues, information disclosure that does not expose personal data or secrets, or UI flaws that could mislead a user without changing access or usage records.

Safe testing rules

How to report

Send reports to support@sanad.dev. Include a short title, affected URL or surface, the account email used for testing, clear reproduction steps, expected and actual behavior, security impact, screenshots or screen recordings when useful, and any logs needed to reproduce the issue. Remove secrets, raw tokens, unrelated personal data, and third-party confidential information from the report.

Eligibility and exclusions

Eligible reports must be original, reproducible, affect an in-scope Sanad property, and show a concrete security impact. The first clear report of a duplicate issue is eligible. Out-of-scope findings include missing best-practice headers without exploitability, clickjacking on non-sensitive public pages, reports based only on automated scanner output, leaked credentials from systems Sanad does not control, account enumeration without impact, spam or availability-only testing, and issues requiring access to another person's account, device, mailbox, or browser.

Good-faith research

If you follow this policy and act in good faith, Sanad will treat your research as authorized for the in-scope Sanad systems. This authorization does not apply to third-party services or activity that violates the safe testing rules.

Contact

For questions about scope, testing access, or an active report, contact support@sanad.dev.